Operational rules and controls to prevent data leaks, unauthorized modifications, or privacy breaches.
DATA PROTECTION POLICY
| Document Control | |
| Document Name | Data Protection Policy |
| Reference No. | DJTMPL/IT/POL/DPP |
| Policy Owner | Chief Operation Officer |
| Policy Approving Authority | Board Of Directors |
| Version No. | 1.0 |
| Document Status | Definitive |
| Review Date | 01-04-2026 |
| Compliance Status | Mandatory |
| Next Review Period | 01-04-2027 |
| Security Classification | Internal Use Only |
| Distribution | DJT MICROFINANCE PRIVATE LIMITED |
Revision History
| Version | Date | Change Description |
| 1.0 | 01-04-2026 | First version |
Table Of Content
| S. No | Particulars |
| 1 | Abbreviations |
| 2 | Terms and Definitions |
| 3 | Purpose |
| 4 | Scope |
| 5 | Categories Of Personal Data Collected |
| 6 | Purpose of Data Collection |
| 7 | Notice and Disclosure to Data Principal |
| 8 | Obtaining Consent |
| 9 | Processing Of Personal Data |
| 10 | Retention Of Personal Data |
| 11 | Sharing Of Personal Data |
| 12 | Data Security |
| 13 | Rights Of Data Principal |
| 14 | Data Principal Access Request |
| 15 | Privacy by Design |
| 16 | Governance And Accountability |
| 17 | Policy Compliance |
1. Abbreviations
| Abbreviation | Full Form |
| DPDP Act | Digital Personal Data Protection Act, 2023 |
| e-KYC | Electronic Know Your Customer |
| KYC | Know Your Customer |
| MFI | Microfinance Institution |
| NBFC | Non-Banking Financial Company |
| NDA | Non-Disclosure Agreement |
| OTP | One-Time Password |
| PII | Personally Identifiable Information |
| RBI | Reserve Bank of India |
| UIDAI | Unique Identification Authority of India |
| VID | Virtual ID |
2. Terms and Definitions
| Term | Definition |
| Aadhaar Number | Identification number issued to an individual under Section 3 of the Aadhaar (Targeted Delivery of Financial and other Subsidies, Benefits and Services) Act, 2016, including any Virtual ID issued in lieu thereof. |
| Anonymization | Irreversible process of transforming personal data such that an individual cannot be identified from it. |
| Consent | Free, informed, specific, clear, and withdrawable affirmative action given by the Data Principal before processing of their personal data. |
| Data Fiduciary | DJT Microfinance PVT. LTD., as the entity that determines the purpose and means of processing personal data. |
| Data Principal | The individual whose personal data is being collected or processed (e.g., customer, borrower). |
| De-identification | Process of removing or masking identifiers from personal data so that the individual cannot be directly identified. |
| Personal Data | Data about or relating to a natural person who is directly or indirectly identifiable, including any inference drawn for profiling. |
| Processing | Any operation on personal data — collection, storage, use, sharing, transfer, erasure, or destruction. |
| Sensitive Personal Data | Includes financial information (bank account, credit/debit card), biometric information, health data, and Aadhaar-related identity information. |
| Virtual ID (VID) | An alternative virtual identity issued as a substitute for the Aadhaar number for authentication purposes. |
3. Purpose
The purpose of this policy is to provide clear direction to all employees, management, and relevant stakeholders of DJT Microfinance PVT. LTD. on the collection, use, storage, sharing, and disposal of personal data — particularly in the context of:
- Compliance with the Digital Personal Data Protection (DPDP) Act, 2023
- Compliance with RBI guidelines on KYC / e-KYC for NBFCs and Microfinance Institutions
- Compliance with the Aadhaar Act, 2016, its amendments, and UIDAI regulations
- Alignment with Companies Act, 2013 obligations on data governance and fiduciary duties
- Protection of customer and employee personal data from unauthorized access, misuse, or breach
DJTMPL, in the conduct of its microfinance business, collects sensitive personal and financial data from customers, employees, and business partners. This policy ensures that such data is handled responsibly, lawfully, and transparently.
4. Scope
This policy applies to:
- All employees of DJTMPL (permanent, contractual, and temporary)
- All third-party service providers, agents, and vendors with access to DJTMPL data
- All forms of personal data — whether in physical (paper) or digital (electronic) format
- All systems, applications, and databases used to collect, process, or store personal data
Personal data in scope includes — but is not limited to — customer KYC data, Aadhaar-based identity information, financial records, loan account data, employee records, and any other data that can identify an individual.
5. Categories of Personal Data Collected
DJTMPL collects only the minimum data necessary for lawful business purposes. The following categories of data are collected:
| Category | Examples | Protection Level |
| Customer Identity | Name, address, date of birth, photograph | High |
| Financial Data | Bank account, loan details, repayment history | High |
| KYC / e-KYC Data | Aadhaar number / VID, PAN, Voter ID, Passport | Critical |
| Biometric Data | Fingerprint, iris scan (used for Aadhaar authentication) | Critical |
| Contact Information | Mobile number, email address, mailing address | Medium |
| Employment / Income | Employer details, income proof, salary slips | High |
| Internal Records | Loan files, audit logs, board resolutions | Medium |
Data collection shall be limited to what is necessary for the specific, stated purpose (principle of data minimization). Aadhaar numbers shall only be collected where explicitly permitted under the Aadhaar Act 2016 and RBI KYC Master Direction.
6. Purpose of Data Collection
Personal data shall only be collected and processed for the following legitimate purposes:
- Customer onboarding and KYC verification as mandated under RBI KYC Master Direction
- e-KYC authentication via UIDAI for account opening and loan processing
- Loan appraisal, disbursement, and repayment tracking
- Compliance with Anti-Money Laundering (AML) and PMLA obligations
- Credit bureau reporting as required by RBI
- Customer service, grievance handling, and complaint resolution
- Regulatory reporting to RBI, NABARD, or other statutory authorities
- Internal audit, risk management, and legal proceedings
Personal data shall not be used beyond the purpose for which it was collected. Any new use of existing data shall require a fresh notice to, and consent from, the data principal, unless otherwise exempted under applicable law.
7. Notice and Disclosure to Data Principal
Prior to collecting personal data, DJTMPL shall provide the following information to each data principal (customer/individual) in clear and simple language:
- The purpose for which personal data / identity information is being collected
- The types of data being collected and how they will be used
- Whether submission of Aadhaar number is mandatory or voluntary, and the legal provision mandating it, if applicable
- Alternatives to Aadhaar-based identification where available (e.g., PAN, Passport, Voter ID)
- The right to use Virtual ID (VID) in lieu of Aadhaar number for authentication
- Details of the Privacy Officer and contact information for queries or complaints
- That the data principal has the right to withdraw consent and the process for doing so
Authentication notifications: The data principal shall be notified via SMS or email at the time of Aadhaar authentication. DJTMPL shall maintain logs of all such notifications.
8. Obtaining Consent
DJTMPL shall obtain explicit, informed, and recorded consent from the data principal before collecting and processing their personal data. The following conditions apply:
- Consent shall be free, specific, informed, clear, and withdrawable
- Consent shall be obtained in writing or in electronic form (on DJTMPL application, website, or system)
- For sensitive personal data (including Aadhaar and financial information), explicit consent shall be obtained separately
- DJTMPL shall maintain logs of consent, including the information disclosed and the date and method of consent
- The Legal / Compliance team shall vet the consent mechanism and formally approve it
- Consent shall not be bundled as a pre-condition for providing services unless the data is strictly necessary for that service
- Data principals may withdraw consent at any time; DJTMPL shall provide a simple and accessible mechanism for withdrawal
9. Processing of Personal Data
Personal data collected by DJTMPL shall be processed in compliance with applicable law and only for the purposes for which it was collected. The following principles govern all processing activities:
9.1 Aadhaar / e-KYC Data
- Aadhaar number / VID, biometric, and demographic data collected during e-KYC shall only be used for UIDAI authentication
- DJTMPL shall not use Aadhaar data for any purpose beyond what is permitted under RBI Master Direction DBR.AML.BC.No.81/14.01.001/2015-16
- Demographic details received from UIDAI shall be used only for customer identification for the specific service and duration of the service
- DJTMPL has been classified as a Local AUA by UIDAI and shall not store Aadhaar numbers in its systems — only UID Tokens shall be stored
9.2 General Processing Principles
- Lawfulness — all processing shall have a legal basis (consent, contract, legal obligation, or legitimate interest)
- Purpose limitation — data shall be used only for the stated purpose
- Data minimization — only the minimum data necessary shall be collected
- Accuracy — data shall be kept accurate and up to date
- Storage limitation — data shall not be retained longer than necessary
- Security — appropriate technical and organisational measures shall protect data
10. Retention of Personal Data
DJTMPL shall retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law, whichever is later.
| Data Category | Retention Period | Legal Basis |
| KYC Records (physical & digital) | 5 years after account closure | RBI KYC Master Direction |
| Authentication / e-KYC Transaction Logs | 2 years active | UIDAI / Aadhaar (Data Security) Regs, 2016 |
| Loan Account Records | 8 years post loan closure | PMLA, 2002 |
| Employee Records | Duration of employment + 5 years | Companies Act, 2013 / Labour laws |
Upon expiry of the retention period, personal data shall be securely deleted or anonymized unless retention is required by a court order or pending legal proceeding.
11. Sharing of Personal Data
DJTMPL shall not share personal data with third parties except in the following circumstances:
- As required by RBI, NABARD, SEBI, or other regulatory / statutory authorities
- As required for credit bureau reporting (CIBIL, Equifax, CRIF, Experian) per RBI mandate
- With service providers engaged under a formal contract with confidentiality and data protection obligations (NDA / DPA)
- With collection agencies or legal counsel in the course of lawful debt recovery
- With auditors and regulators for compliance and inspection purposes
- With the explicit, recorded consent of the data principal for any other purpose
Sharing Restrictions:
- Biometric information shall not be transmitted over any network without encryption and PID block creation as required under Aadhaar Act
- Aadhaar numbers shall not be transmitted over the internet unless via a secure, encrypted channel
- Identity information shall not be shared in contravention of the Aadhaar Act or UIDAI circulars
- Identity information shall not be hosted or transferred outside the territory of India
12. Data Security
DJTMPL shall implement appropriate technical and organizational measures to protect personal data from unauthorized access, loss, misuse, or breach. These include:
12.1 Technical Controls
- All Aadhaar/KYC data shall be collected over a secure application and transmitted over encrypted channels as per UIDAI specifications
- e-KYC data shall be stored in encrypted form compliant with UIDAI encryption standards
- Biometric devices used for Aadhaar authentication shall be STQC/UIDAI certified
- OTP collected for authentication shall be encrypted at the device level before transmission
- Access to authentication applications, audit logs, and source code shall be restricted to authorized personnel only
- An Access Control List (ACL) shall be maintained and reviewed regularly
- Aadhaar numbers, where applicable, shall be stored only in Aadhaar Data Vault (ADV) per UIDAI specifications
12.2 Organizational Controls
- All applications used for Aadhaar authentication or e-KYC shall be tested for compliance annually by STQC/CERT-IN certified auditors
- NDAs shall be in place for all employees, contractors, consultants, and agencies handling personal data
- Staff involved in KYC / Aadhaar processing shall be trained on data privacy obligations on a periodic basis
- An Information Security Policy aligned with ISO 27001 and the DPDP Act shall be maintained
- Best practices in data privacy and protection based on international standards shall be adopted
12.3 Breach Notification
In the event of a personal data / identity information breach, DJTMPL shall:
- Notify the relevant authority (UIDAI / CERT-IN / RBI as applicable) with: a description and consequences of the breach, number of individuals affected, measures taken to mitigate the breach, and the Privacy Officer's contact details
- Notify affected data principals as required under the DPDP Act, 2023
- Document the breach, investigation findings, and remediation steps
13. Rights of Data Principals
Under the DPDP Act, 2023 and applicable regulations, data principals (customers / individuals) have the following rights:
| Right | Description & DJTMPL's Obligation |
| Right to Information | Data principal may request information about what personal data DJTMPL holds about them and how it is being used |
| Right to Correction | Data principal may request correction or update of inaccurate / incomplete personal data. Where updates require UIDAI verification, the data principal shall be informed accordingly |
| Right to Erasure | Data principal may request deletion of their personal data where no longer necessary. Core biometric data is protected under Section 29 of the Aadhaar Act and cannot be returned or deleted on request |
| Right to Withdraw Consent | Data principal may withdraw consent for processing at any time. DJTMPL shall delete the relevant e-KYC data in a verifiable manner and provide written acknowledgement |
| Right to Grievance Redressal | Data principal may lodge a complaint with the Privacy Officer. If unresolved, the data principal may seek redressal under Section 33B of the Aadhaar Act, 2016 or under DPDP Act mechanisms |
14. Data Principal Access Requests
DJTMPL shall establish and maintain a formal process for handling data principal requests:
- All requests shall be formally recorded and acknowledged within 3 working days
- Identity of the data principal shall be verified before providing access to any personal data
- Requests shall be responded to within a reasonable period as prescribed under applicable law
- Compliance with the relevant data protection and privacy laws shall be ensured for all requests
- A dedicated channel (email / helpdesk) shall be made available for data principal requests
15. Privacy by Design
DJTMPL shall embed data privacy principles at the design stage of any new system, product, process, or technology involving personal data processing. This includes:
- Conducting a Privacy Impact Assessment (PIA) before launching any new data processing activity
- Ensuring disclosure / consent mechanisms are in place before going live with any new process
- Implementing anonymization, de-identification, and data minimization wherever feasible
- Ensuring that Aadhaar numbers are not published or exposed in any database or report — they must be redacted or blacked out in print and electronic form
- Conducting quarterly self-assessments to ensure ongoing compliance with disclosure of information and consent requirements
16. Governance and Accountability
16.1 Privacy Officer
DJTMPL shall designate a Privacy Officer (Data Protection Officer) responsible for:
| Detail | Information |
| Designation | Privacy / Data Protection Officer |
| Reporting To | Chief Information Officer / CISO |
| Key Responsibilities |
|
16.2 Privacy Committee
A Privacy Committee shall be established to provide strategic direction on privacy matters. The committee shall include representation from IT, Legal/Compliance, Operations, and Senior Management.
16.3 Board-Level Accountability
In accordance with the Companies Act, 2013, the Board of Directors of DJTMPL bears fiduciary responsibility for data governance. The Board shall:
- Approve and periodically review this Data Protection Policy
- Ensure adequate resources are allocated for data protection compliance
- Receive periodic reports on the status of data protection compliance and any material incidents
16.4 Implementation Responsibility
| Responsibility | Role / Designation |
| Policy Monitoring & Enforcement | Chief Audit Officer |
| Controls Implementation | Chief Business Officer |
| Consent & Disclosure Review | Chief Business Officer / Legal Head |
| IT / Technical Controls | Group IT Head |
| Policy Communication | Privacy Officer / HR Head |
17. Policy Compliance
17.1 Compliance Measurement
The Infosec / Compliance team shall verify adherence to this policy through internal audits, system reviews, and regulatory inspection readiness checks. The Privacy Officer shall conduct quarterly self-assessments and present findings to the Privacy Committee.
17.2 Exceptions
Requests for exceptions must have a documented business justification and associated risk assessment. Exceptions must be approved by the Group IT Head and Top Management, are time-bound, and shall be re-evaluated upon expiry.